Hackers Use Spoofed OAuth Client IDs to Slip Past Microsoft Entra Monitoring

Hackers Use Spoofed OAuth Client IDs to Slip Past Microsoft Entra Monitoring
Hackers Use Spoofed OAuth Client IDs to Slip Past Microsoft Entra Monitoring

Cybersecurity researchers have identified a new attack method that lets hackers collect Microsoft Entra user information while evading many of the platform’s standard security alerts.

According to cybersecurity firm Proofpoint, attackers are increasingly relying on spoofed OAuth client IDs to mask their activity, making it harder for security teams to spot account enumeration and credential validation attempts.

OAuth client IDs are used by Microsoft Entra to identify applications requesting access to user data. By forging these IDs, attackers can try to verify usernames and passwords without running a legitimate or trusted application.

Why the technique is hard to detect

Proofpoint said the approach lets threat actors determine whether accounts and passwords are valid without generating successful sign-in events, lowering the chance of tripping traditional security monitoring.

The spoofed client IDs also leave the application field blank in Microsoft Entra logs, making it difficult for security teams to flag suspicious activity through application-based monitoring. As a result, compromised credentials can go unnoticed even when account enumeration attempts are caught.

Researchers also found the method can bypass conditional access policies set up for specific applications, allowing attackers to sidestep another key layer of cloud security.

Two large-scale campaigns

Proofpoint identified two large campaigns using the technique. One, which began in January, deployed more than 700,000 spoofed client IDs to target over one million user accounts across nearly 4,000 organizations. A second campaign, first seen in December with another wave in February, was even bigger, using roughly 3.7 million spoofed IDs to target more than two million users.

The firm warned that the rising use of spoofed client IDs suggests the technique is gaining traction among threat actors targeting cloud environments.

How organizations can respond

To reduce risk, Proofpoint advised organizations to monitor Microsoft Entra logs for sign-in attempts with blank application IDs and to investigate the Entra error code AADSTS700016, which is linked to unrecognized application IDs.

Ahmed Al-Khalifa

Experienced News Reporter with a demonstrated history of working in the broadcast media industry. Skilled in News Writing, Editing, Journalism, Creative Writing, and English. Strong media and communication professional graduated from University of U.T.S

Latest from Blog